Skip to content

Commit 8442e96

Browse files
committed
updated content and screenshot
1 parent f40162f commit 8442e96

File tree

4 files changed

+7
-12
lines changed

4 files changed

+7
-12
lines changed
174 KB
Loading

defender-endpoint/threat-analytics.md

Lines changed: 6 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ ms.custom:
1919
- cx-ta
2020
ms.topic: conceptual
2121
ms.subservice: edr
22-
ms.date: 10/18/2024
22+
ms.date: 11/12/2024
2323
---
2424

2525
# Track and respond to emerging threats through threat analytics
@@ -60,21 +60,16 @@ Each report provides an analysis of a tracked threat and extensive guidance on h
6060

6161
## Required roles and permissions
6262

63-
The following table outlines the roles and permissions required to access threat analytics. Roles defined in the table refer to custom roles in individual portals and aren't connected to global roles in Microsoft Entra ID, even if similarly named.
63+
The following roles and permissions are required to access Threat analytics in the Defender portal:
64+
- **Security data basics (read)**—to view threat analytics report, related incidents and alerts, and impacted assets
65+
- **Vulnerability management (read)** and **Secure Score (read)**—to see related exposure data and recommended actions
6466

65-
| **One of the following roles are required for Microsoft Defender XDR** | **One of the following roles are required for Microsoft Defender for Endpoint** | **One of the following roles are required for Microsoft Defender for Office 365** | **One of the following roles are required for Microsoft Defender for Cloud Apps and Microsoft Defender for Identity** | **One of the following roles is required for Microsoft Defender for Cloud** |
66-
|---------|---------|---------|---------|---------|
67-
| Threat analytics | Alerts and incidents data: <ul><li>View data- security operations</li></ul>Defender Vulnerability Management mitigations:<ul><li>View data - Threat and vulnerability management</li></ul> | Alerts and incidents data:<ul> <li>View-only manage alerts</li> <li>Manage alerts</li> <li>Organization configuration</li><li>Audit logs</li> <li>View-only audit logs</li><li>Security reader</li> <li>Security admin</li><li>View-only recipients</li> </ul> Prevented email attempts: <ul><li>Security reader</li> <li>Security admin</li><li>View-only recipients</li> | <ul><li>Global admin</li> <li>Security admin</li> <li>Compliance admin</li> <li>Security operator</li> <li>Security reader</li></ul> | <ul><li>Global admin</li><li>Security admin</li></ul> |
67+
By default, access to services available in the Defender portal are managed collectively using [Microsoft Entra global roles](/defender-xdr/m365d-permissions). If you need greater flexibility and control over access to specific product data, and aren't yet using the [Microsoft Defender XDR Unified role-based access control (RBAC)](/defender-xdr/manage-rbac) for centralized permissions management, we recommend creating custom roles for each service. [Learn more about creating custom roles](/defender-xdr/custom-roles)
6868

6969
>[!IMPORTANT]
7070
> Microsoft recommends that you use roles with the fewest permissions. This helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
7171
>
72-
> You'll have visibility to all threat analytics reports even if you have just one of the products and its corresponding roles described in the previous table. However, you're required to have each product and roles to see that product’s specific incidents, assets, exposure, and recommended actions associated with the threat.
73-
74-
Learn more:
75-
- [Custom roles in role-based access control for Microsoft Defender XDR](/defender-xdr/custom-roles)
76-
- [Microsoft Defender XDR Unified role-based access control (RBAC)](/defender-xdr/manage-rbac)
77-
72+
> You'll have visibility to all threat analytics reports even if you have just one of the products supported. However, you're required to have each product and role to see that product’s specific incidents, assets, exposure, and recommended actions associated with the threat.
7873
7974
## View the threat analytics dashboard
8075

defender-xdr/threat-analytics.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ ms.custom:
2020
- cx-ta
2121
- seo-marvel-apr2020
2222
search.appverid: met150
23-
ms.date: 10/18/2024
23+
ms.date: 11/12/2024
2424
---
2525

2626
# Threat analytics in Microsoft Defender XDR
174 KB
Loading

0 commit comments

Comments
 (0)